Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
ID: f762d5bc-95f3-5a76-bb9d-f9942dc0302b
STIX ID: report--f762d5bc-95f3-5a76-bb9d-f9942dc0302b
Feed Name: Securelist by Kaspersky
### Executive summary In July 2026 Kaspersky documented a sophisticated Head Mare APT campaign that chained two TrueConf Server vulnerabilities to upload a web shell, escalate to SYSTEM, and replace legitimate TrueConf client installers with binaries containing the PhantomCore backdoor and PhantomGraph modules; vendor patches were released for TrueConf Server versions 5.3.9, 5.4.9 and 5.5.5. The report includes detailed IOCs (file hashes, IPs, domains, registry keys, service names, file paths), YARA and detection rules, observed attacker commands and persistence mechanisms, and recommends installing updates, verifying installer signatures, and monitoring specified events and indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
